The victim recognized the face. She recognized the voice. Both were fake.

Key points

  • Fake AI-generated videos were used to promote fraudulent investment platforms.
  • An 86-year-old person lost $900,000, another lost more than $30,000.
  • The Autorité des marchés financiers received 108 deepfake reports between 2023 and 2025.
  • The safeguard is not technological but procedural: out-of-band verification.

What happened in this fraud?

Fraudsters distributed AI-generated fake videos on Facebook and YouTube, with cloned voices and faces, appearing to endorse cryptocurrency platforms. Victims were directed to fraudulent websites and encouraged to invest progressively.

The toll is heavy. An 86-year-old person lost $900,000; another lost more than $30,000. Between January 2023 and December 2025, the Autorité des marchés financiers received 108 deepfake reports.

Gradual escalation is the pattern that keeps showing up in these cases. Fraudsters don’t ask for $900,000 upfront: they secure a modest first payment, display a fabricated return, then encourage a larger second payment. Each step looks reasonable next to the one before it.

Why should businesses care about this fraud?

Because the same technique is already targeting organizations, known as CEO fraud: an executive is impersonated by email, by phone, and now on video calls, to push through an urgent wire transfer. What has changed is not the scenario but its production cost.

flowchart LR A[AI clones voice + face] --> B[Convincing fake video] B --> C[Fraudulent platform] C --> D[Victim wire transfers]

Generative AI industrializes deception. Producing a credible video of a well-known person now takes a few clicks, where it once required real production resources. The Canadian Anti-Fraud Centre documents this pattern among rising fraud types.

The practical consequence for internal controls is stark: a recognized voice and a recognized face no longer prove anything. Yet many payment procedures still implicitly rely on that proof.

How can you protect against it without buying a tool?

Through a procedural rule, not a technology. Every payment and every change of banking details gets confirmed through a channel different from the one used to make the request, with a known contact, using a number already on file. The urgent request is precisely the one that needs to be slowed down.

  • Out-of-band verification. If the request comes by email, confirm by phone; if it comes by phone, call back on the number in the internal directory, never the one provided in the request.
  • A clear rule, shared across the whole team. No urgency justifies bypassing the procedure, and no one should be blamed for taking five minutes to verify. This second part matters as much as the first.
  • Awareness training. What your teams know how to recognize, they don’t fall for. Showing a deepfake example in a workshop works better than a memo.
  • A frictionless reporting channel. Someone with doubts should be able to raise them in thirty seconds, without fear of looking foolish.

RISS trains your teams on AI-assisted fraud and sets up the verification procedures that cut fabricated urgency short.

FAQ

Can a deepfake still be spotted by eye?

Less and less, and that’s not the right approach anyway. Classic artifacts, missing blinks or imperfect lip sync, disappear with each new generation of tools. Relying on visual detection means chasing a technology that improves faster than the eye can follow. The defense that holds up is procedural: it doesn’t depend on how good the fake is, only on the channel used to confirm the request.

Our executives have little public exposure. Are we safe?

Less targeted, not safe. A few seconds of voice are enough for current tools, and those seconds are often found in a phone greeting, a local interview, or a corporate video. Besides, a deepfake isn’t even necessary: CEO fraud still works very well with a simple email using a spoofed display name, which remains the most common case.

What should we do if a fraudulent wire transfer has gone out?

Act within the hour, in this order. Contact your financial institution to attempt a fund recall, which is only possible very early on. Report it to the Canadian Anti-Fraud Centre and to your local police service. Preserve all messages and call logs without altering them. Then check whether any personal information was affected, since that triggers your obligations under Law 25.

Sources